Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
41987
Total
3420
Critical
12405
High
12324
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-20275 | HIGH | 8.8 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security … | Sep 02, 2026 |
| CVE-2026-20274 | CRITICAL | 9.8 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security … | Sep 02, 2026 |
| CVE-2026-20212 | CRITICAL | 9.8 | A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with root privileges. This … | Sep 02, 2026 |
| CVE-2026-84838 | HIGH | 7.8 | A flaw was found in rpmuncompress. This command injection vulnerability allows a local attacker to execute arbitrary commands. This occurs when rpmuncompress processes a specially … | Sep 02, 2026 |
| CVE-2026-84837 | HIGH | 7.8 | A flaw was found in rpm. An attacker can exploit a command injection vulnerability by influencing the path or filename of a tarball processed by … | Sep 02, 2026 |
| CVE-2026-84677 | MEDIUM | 5.4 | Jenkins update-center2 3.18.3 and earlier does not escape plugin-provided values (plugin names, descriptions, and version metadata) on plugin download index pages, resulting in a stored … | Sep 02, 2026 |
| CVE-2026-84676 | MEDIUM | 4.3 | Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier stores tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by … | Sep 02, 2026 |
| CVE-2026-84675 | HIGH | 7.4 | OS command injection vulnerability in Jenkins TICS Plugin 2025.1.1 and earlier allows attackers able to control build environment variable values to execute arbitrary commands on … | Sep 02, 2026 |
| CVE-2026-84674 | MEDIUM | 5.4 | Missing permission checks in Jenkins XebiaLabs XL Deploy Plugin 26.1.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in … | Sep 02, 2026 |
| CVE-2026-84673 | HIGH | 8.8 | Jenkins Customizable Header Plugin 295.v2544b_ca_19b_97 and earlier allows overwriting the plugin's appearance configuration through Stapler data binding, allowing attackers to configure a custom SVG icon … | Sep 02, 2026 |
| CVE-2026-84672 | HIGH | 8.8 | Jenkins Microsoft Entra ID (previously Azure AD) Plugin 710.v0b_ff8e9cc2d2 and earlier grants Entra group permissions using both the group's unique object ID and its display … | Sep 02, 2026 |
| CVE-2026-84671 | HIGH | 8.8 | Jenkins File Parameter Plugin 425.v3fa_801681b_5e and earlier allows writing files to arbitrary locations on the Jenkins controller file system through Stapler data binding, which can … | Sep 02, 2026 |
| CVE-2026-84670 | HIGH | 8.8 | Jenkins Performance Plugin 1015.v09ca_52b_3370e and earlier does not restrict the classes that can be instantiated when deserializing cached performance reports stored in the build directory … | Sep 02, 2026 |
| CVE-2026-84669 | HIGH | 8.8 | A path traversal vulnerability in Jenkins Allure Plugin 2.35.2 and earlier allows attackers with Item/Read permission on jobs that publish Allure report results to read … | Sep 02, 2026 |
| CVE-2026-84668 | HIGH | 8.8 | Jenkins SAML Plugin 4.618.v441a_27fa_46d2 and earlier allows overwriting the SAML identity provider metadata file through Stapler data binding, allowing attackers to replace it with attacker-controlled … | Sep 02, 2026 |
| CVE-2026-84667 | HIGH | 7.1 | Jenkins ThinBackup Plugin 2.1.4 and earlier allows overwriting the plugin's backup configuration through Stapler data binding, allowing attackers to redirect backup writes to an attacker-specified … | Sep 02, 2026 |
| CVE-2026-84666 | UNKNOWN | — | Jenkins Job Configuration History Plugin 1367.vc8fa_b_15101dc and earlier allows overwriting the plugin's history recording configuration through Stapler data binding, allowing attackers to redirect history storage … | Sep 02, 2026 |
| CVE-2026-84665 | HIGH | 8.0 | Jenkins SonarQube Scanner Plugin 2.18.3 and earlier does not limit URL schemes for the dashboard links it creates based on SonarQube scanner results, allowing the … | Sep 02, 2026 |
| CVE-2026-84664 | MEDIUM | 5.4 | Jenkins GitLab Plugin 1.9.16 and earlier allows overwriting the global GitLab connection configuration through Stapler data binding, allowing attackers to connect to an attacker-specified URL … | Sep 02, 2026 |
| CVE-2026-84663 | MEDIUM | 5.4 | A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline: Groovy Libraries Plugin 798.v5cc688825312 and earlier allows attackers to delete shared library caches. | Sep 02, 2026 |
| CVE-2026-84662 | MEDIUM | 4.3 | Jenkins LDAP Plugin 807.809.vd3a_4e5e4ec98 and earlier allows connecting to a specified URL through Stapler data binding, allowing attackers to connect to an attacker-specified URL. | Sep 02, 2026 |
| CVE-2026-84661 | MEDIUM | 5.4 | A missing permission check in Jenkins Pipeline: Build Step Plugin 599.v4b_67ea_11b_152 and earlier causes downstream builds awaited by the `waitForBuild` step when the `propagateAbort` parameter … | Sep 02, 2026 |
| CVE-2026-84660 | MEDIUM | 5.4 | A missing permission check in Jenkins Pipeline: Build Step Plugin 599.v4b_67ea_11b_152 and earlier causes downstream builds triggered by the `build` step to be canceled even … | Sep 02, 2026 |
| CVE-2026-84659 | MEDIUM | 4.3 | Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier does not enforce a permission check in the method that controls the "Force the use of the sandbox … | Sep 02, 2026 |
| CVE-2026-84658 | MEDIUM | 4.3 | Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier uses the `@DataBoundConstructor` annotation on a constructor that loads script approval configuration, allowing attackers able to submit certain … | Sep 02, 2026 |